Hi,
We have LF Forms synching users once every 24 hours. We are a pure SAML environment, no Windows users or groups. However, during the LF Forms user sync, we get this error every time:
An error occurred when searching for groups in Active Directory our.domain.ca [LFF3022-InvalidLfdsADDomain]
Message: An invalid dn syntax has been specified.
No Active Directory group 'S-1-9-12246445-....' found. The system account the Laserfiche Forms Routing Service runs under must be assigned the "ReadMemberOf" right for User objects in order to get the groups information for the Windows users in the Active Directory domain to be able to synchronize the Windows users.
Function: GetUserDescendantsInAD
The service account that runs all LF services has full read access to our AD environment.
I've looked everywhere in LFDS, Forms and cannot for the life of me find where it's trying to sync an AD group. We only have SAML users and SAML groups. I've turned off all domain syncs from within LFDS as well. Any insight on how to solve these Windows Error log messages?
Thanks.